TopTgm
kubesploit

Kubesploit

Locale: en
Subscribers:1.78K
Category: technology
Description:
News and links on Kubernetes security curated by the https://kubesploit.io/
Kubernetes profiling, enabled by default in the API server, scheduler, controller-manager, etc., can pose a security risk if not properly managed.

While the information is gated behind authz & authn, certain clusters can still be vulnerable to attacks.

More:
10/24/2024, 6:06:09 PM
This week's 6 best Kubernetes vacancies that focus on security are:

DevSecOps Engineer with Worldcoin
πŸ’° $236K to $323K a year
🏠 From the office in San Francisco, CA, USA
β†’

DevSecOps Engineer with Gemini
πŸ’° $248K to $310K a year
πŸ‘¨β€πŸ’» Remote from the United States
β†’

DevSecOps Engineer with Uniswap Labs
πŸ’° $264K to $294K a year
🏠 From the office in New York, NY, USA
β†’

DevSecOps Engineer with CoreWeave
πŸ’° $240K to $275K a year
πŸ πŸƒπŸ»β€β™‚οΈπŸŒŽ Roseland, NJ / Brooklyn, NY / Sunnyvale, CA / Bellevue, WA, USA
β†’

πŸ‘‰ Browse all 1302 Kubernetes jobs on Kube Careers
10/23/2024, 9:41:03 PM
This tutorial demonstrates how to set up a zero-trust Kubernetes ingress with Tailscale operator, cert-manager, and external-dns.

The configuration enables easy and rapid deployment of private ingresses accessible only to authorized devices.

More:
10/23/2024, 6:11:03 PM
This week on the Learn Kubernetes Weekly:

πŸš‰ How we are managing a container platform
πŸ’§ Leaky Vessels deep dive: escaping from Docker one syscall at a time
πŸ•΅οΈβ€β™€οΈ How to inspect Kubernetes networking
πŸ”§ Removing specific images from all Kubernetes nodes
🌎 Kubernetes resiliency (RTO/RPO) in multi-cluster deployments

Read it now:

πŸ™ Many thanks to StormForgeIO for supporting our work and sponsoring this issue. Make sure to check out their platform to optimise resources and save on your cloud spend
6/5/2024, 12:55:05 PM
The "TunnelVision" attacks reinforce the need for a new security paradigm.

In this article, you will explore how this type of attack can be mitigated in the future and what tools you need.

More:
6/4/2024, 6:05:06 PM
In this KubeFM episode, Hans, a Principal Cloud engineer, shares his experiences empowering teams to use, build and manage platforms built on Kubernetes.

You will learn:

- How OpenTelemetry and Prometheus shape cluster management and observability.
- The role of tools like ArgoCD and Flux in enabling GitOps and streamlining deployment processes.
- The significance of governance tools such as Gatekeeper and OPA for secure and validated resource creation.
- The benefits of Custom Resource Definitions (CRDs) and operators in automating processes and enhancing the developer experience.

Watch (or listen to) it here:

πŸ™ Many thanks to Sysdig for supporting our work and sponsoring this episode. Make sure to check out their Kubernetes security checklist

With "Zero certified" Farrell
6/4/2024, 12:05:25 PM
In this article, you will learn about Istio AuthorizationPolicies and how they function, as well as use an alternative approach to declare them using IBAC (Intent-Based Access Control)

More:
5/31/2024, 6:09:03 PM
Ben Hirschberg, ARMO's CTO, discusses managing network policies at scale By monitoring development and staging clusters and analyzing application behaviour.

This automated process ensures robust network segmentation, closely aligning with zero-trust principles.

Watch the full interview:

This interview is a reaction to Ori's episode
5/31/2024, 4:14:29 PM
The article discusses automating the building, signing, and verifying of Docker images using tools like Kaniko, Cosign, and Kyverno.

It explains how these tools can be integrated into a GitLab CI/CD pipeline to improve efficiency and security.

More:
5/30/2024, 6:06:03 PM
This week's 6 best Kubernetes vacancies that focus on security are:

DevSecOps Engineer with Applied Intuition
πŸ’° $65K to $400K a year
🏠 From the office in Mountain View, CA, USA
β†’

DevSecOps Engineer with Hyperscience
πŸ’° $190K to $260K a year
πŸ‘¨β€πŸ’» Remote from the United States
β†’

DevSecOps Engineer with Crusoe
πŸ’° $210K to $240K a year
🏠 From the office in San Francisco, CA, USA
β†’

DevSecOps Engineer with Opal Security
πŸ’° $140K to $260K a year
πŸ πŸƒπŸ»β€β™‚οΈπŸŒŽ San Francisco, CA / New York, NY, USA
β†’

DevSecOps Engineer with iHerb
πŸ’° $162.19K to $221.17K a year
🏠 From the office in Irvine, CA, USA
β†’

πŸ‘‰ Browse all 442 Kubernetes jobs on Kube Careers
5/29/2024, 9:10:03 PM
Learn how Snyk security researchers uncovered the Leaky Vessels container breakout Docker vulnerabilities that allow a malicious attacker to break out of a container environment with a controlled Dockerfile under docker build and docker run.

More:
5/29/2024, 6:05:06 PM
This week on the Learn Kubernetes Weekly:

πŸ₯· Kubernetes webhook used by attackers
πŸ‘¨πŸ»β€πŸ’Ό When is admin not admin? When it's super-admin!
πŸ“† Kubernetes HPA based on events in Google Calendar
πŸ”€ Seamless data exchange with Kafka Connect and Strimzi on Kubernetes at Decathlon
πŸ›‘ Database in Kubernetes: is that a good idea?

Read it now:

πŸ™ Many thanks to Otterize for supporting our work and sponsoring this issue. Make sure to check out their intent-based access control platform (and related open-source projects)
5/29/2024, 12:35:04 PM
This week's 6 best Kubernetes vacancies that focus on security are:

DevSecOps Engineer with Anthropic
πŸ’° $300K to $405K a year
πŸ πŸƒπŸ»β€β™‚οΈπŸŒŽ San Francisco, CA / New York, NY, USA
β†’

DevSecOps Engineer with Plaid
πŸ’° $215.3K to $322.9K a year
πŸ‘¨β€πŸ’» Remote from the United States
β†’

DevSecOps Engineer with Applied Intuition
πŸ’° $65K to $400K a year
🏠 From the office in Mountain View, CA, USA
β†’

DevSecOps Engineer with Hyperscience
πŸ’° $190K to $260K a year
πŸ‘¨β€πŸ’» Remote from the United States
β†’

DevSecOps Engineer with Crusoe
πŸ’° $210K to $240K a year
🏠 From the office in San Francisco, CA, USA
β†’

πŸ‘‰ Browse all 447 Kubernetes jobs on Kube Careers
5/1/2024, 9:10:05 PM
Container image hardening involves adhering to best practices, monitoring vulnerabilities, and enhancing container security.

This article provides guidelines to mitigate risks in running Docker containers in production.

More:
5/1/2024, 6:05:07 PM
This week on the Learn Kubernetes Weekly:

πŸ‘† Moving up the stack
βœ‚οΈ Cut container startup time
😈 Abusing Distroless
πŸ₯· Hacking Kubernetes in AWS
πŸ€” 2vCPU app run faster in a VM than in a container

Read it now:
5/1/2024, 11:55:09 AM
KBOM (Kubernetes Bill of Materials) is a CLI tool that can generate a software bill of materials for your Kubernetes cluster.

More:
4/30/2024, 6:05:03 PM
In this KubeFM episode, Alexander Block delves into the intricacies of Kubernetes templating and deployment tools, sharing his journey from frustration with existing solutions to creating his tool, kluctl.

Alex also discusses the challenges and solutions in Kubernetes templating and deployment, emphasizing the need for more adaptable tools in the Kubernetes ecosystem.

You will learn:

- The fundamental flaws of Helm and how they impact Kubernetes deployments and tools packaging.
- How tools such as Kustomize, CUE, jsonnet are only a partial solution to templating.
- Alternatives to Helm and the future of Kubernetes resource templating and distribution.

Watch (or listen to) it here:
4/30/2024, 1:13:27 PM
This article teaches how to use the Secrets Store CSI driver to mount secrets to Kubernetes pods and covers how to configure and simulate the CSI driver failover feature.

More:
4/29/2024, 6:08:04 PM
In this article, you'll learn how to secure EKS by intentionally attaching the wrong policies to pods and hacking the cluster.

You will misconfigure AWS Identity and Access Management (IAM) roles for the service accounts (IRSA) feature.

More:
4/26/2024, 6:06:07 PM
This article argues, and demonstrates that Distroless containers are not immune to unconventional hacking methods just because shell programs aren't included in the image.

More:
4/25/2024, 6:08:05 PM

Related Groups

METABLAZE - OFFICIAL COMMUNITY
METABLAZE - OFFICIAL COMMUNITY
technology5.97K

We transform Blockchain and AI technology into immersive entertainment experiences through gaming, storytelling & digital assets. MetaBlaze is where the story becomes the ecosystem.Dear MetaBlazers,It's with a heavy heart to announce that MetaBlaze failed to reach it's fundraising goal by a long shot. This means that MetaBlaze is financially incapable of proceeding to third-party launchpad sales and token launch.All community members who made purchases between February 14th to February 28th, 2024, have been fully refunded. Confirmation emails are on their way.The team is acutely aware of the disappointment and frustration resonating throughout the community. We're heartbroken to have reached this point and share in the colossal disappointment; we feel the utmost sorrow for letting our community down. Most team members can no longer continue working without compensation and must seek new job opportunities. Without them, daily operations are no longer feasible.MetaBlaze's present failure is not necessarily permanent and a couple team members will continue pursuing other viable options, such as possibly passing the torch to an entirely new team or securing funding through other means. We are actively and pursuing these potential opportunities.We acknowledge the damage to the current team's reputation and credibility. Nevertheless, we remain optimistic about MetaBlaze's prospects and are confident that placing the company in the hands of a new team could revitalize both the organization and its community. In the event of such a transition, several team members are dedicated to providing support to facilitate the new team's integration.Any concrete updates regarding these developments will be shared in the group once they are fully confirmed and official.While we thank you for the support, we are very sorry for letting you down. Remain hopeful, all hope is not lost

Tech Mukul - Xiaomi HyperOS Community ?‍??
Tech Mukul - Xiaomi HyperOS Community ?‍??
technology2.23K

Amazing ⭐️ HyperOS updates status for Poco F4 and Redmi K50iWe are here to provide news about each an every update about HyperOS Xiaomi HyperOS updates are closed for all Xiaomi devices ?Install HyperOS "AI Surprise Wallpapers" in your Xiaomi devices Install HyperOS "AI Surprise Wallpapers" in your Xiaomi devices Official Telegram Channel = @TECH_MUKUL

Tech Tuber Rana
Tech Tuber Rana
technology317

welcome to Tech Tuber Rana!? Notcoin now has its own smart contract! Everything is ready, we are just waiting for the official launch...Notcoin utilizes a standard TON jetton smart contract (view on GitHub) (https://github.com/OpenBuilders/notcoin-contract) with some special features:β€’ The jetton administrator can modify the code of the jetton-minter and its full data. This means that Sasha can change the code at any moment: if he wants, he can ban you, if he wants, he can take away coins, if he wants, he can create new coins.Admin Id @jm_nobita

Tech Talk by TnS
Tech Talk by TnS
technology254

This is a Mobile technology related discussion channel. You can chat with members of various regions and get a solution for your tech related problems, ask questions,etc.,TG Channel:- @technspiceWelcome to Tech Talk by TnS! ?Boost Your PC's Speed with These 3 Simple Tricks! You Won't Believe the Results!National Quantum Science and Technology Symposium (NQSTS) Event HighlightsBharatGPT - CoRover.ai and Google Cloud to Unveil India's cutting-edge language modeNetflix Alters Streaming Policy for Indian Films Worldwide

Whale Coin Talk
Whale Coin Talk
technology26.43K

Moby Media’s Discussion Group ?News & Educational Content | FinTech | Web3 | DeFi | TradFi | Gaming | Technology ?Stripe Reenters Crypto, Supports USDC Payments on Multiple BlockchainsStripe, a global payments giant, has announced its reentry into the cryptocurrency space with a focus on stablecoin transactions. This marks a significant shift a decade after Stripe’s initial foray into Bitcoin payments. The company now plans to enable merchants to accept payments in USD Coin (USDC), the second-largest stablecoin by market capitalization and the sixth-largest cryptocurrency overall.?⚑️Just dropped a new video exploring the hype around Stanley Pup, a hot, new meme coin! ? Find out why crypto enthusiasts are talking about StanleyPup and how you can join the movement. ?? Introducing SOLGUN ?In the dynamic landscape of decentralized finance (DeFi) on the Solana network, the need for advanced trading solutions has never been more pronounced. Enter SolGun, a groundbreaking platform designed to redefine the way traders navigate and execute trades in the decentralized marketplace.βœ… Why Solgun stands out βœ…Here are some of the reasons why Solgun stands out:    ? Liquidity Snipping    ? Faster trading experience    ? Copy trading feature    ? Lowest fees    ? 100% revenue sharing? Explore the Snipper bot: @Solgun_snipe_botβ˜‘οΈ AMA & Promo: @WCTMaster

UKISS Technology
UKISS Technology
technology2.94K

UKISS Technology is dedicated to building the next gen decentralised security ecosystem. Powered by the KISS Token, our suite of hardware and software solutions will make top-notch digital security accessible for everyone.GM squad! ? To facilitate better communications and engagements, we are moving our interactions from Telegram to DiscordThis Telegram Group will be switched into an Announcement Channel on 15 March 2024.Head over to Discord and join our UKISS Technology Server today! There will be so much alphas, games and incentives you definitely don’t want to miss out ??

This website is not affiliated with Telegram. Visual content shown here might be copyrighted by rightful owners. No infringement intended.
DISCLAIMER: Infos without tag OFFICIAL posted on website are public, and wo are not responsible for the content on their media. Join or subscribe the info there maybe some risk with you. If you have any issueContact UsPlease!